Asset Inventory Management - Asking The Right Questions

Asset Inventory Management - Novaigu

Cyber asset management can become a full time job in dynamic and large environments. In OT environments, it becomes specially important before of during expansions and upgrades. One vital piece is the Asset Inventory, which plays as a step in cyber assets’ security as well.

Before you can protect your assets, you have to know what they are, where they are located, and who’s responsible for them.

This article covers the preliminary questions you should ask before developing a long-term strategy. Your answers will help you understand how you can benefit from automated tools that help keep track of all your business assets.

Identifying and Classifying Your Assets

You can get started by asking yourself:

  • What assets do we own?
  • What is the value of the asset?
  • How critical they are for our operations?
  • When was the asset purchased or built?
  • What is the expected lifecycle of the asset?
  • Who is responsible for the assets?

Tracking and Locating Your Assets

Once you find a way and make the effort to answer the first set of questions, you next challenge would be answering the following:

  • Are the assets currently tagged and labeled?
  • Is the current registry up to date?
  • Who owns the asset location and management process?
  • How often are we conducting asset audits?
  • Are there missing assets or record discrepancies?
  • Do we have leased or rented assets?
  • Have there been changes in asset location or ownership?

The Big Picture

While the concept of implementing and maintaining an asset inventory may appear simple, having a well-organized and consistently updated asset inventory is vital to the foundation of a successful cybersecurity program, and it can be time and resource intensive. Many existing asset inventories and asset management solutions are cluttered with excessive and irrelevant information, creating confusion rather than clarity, so we should always remember that more is not always better.

At Novaigu, we’ve addressed this challenge by designing our platform to eliminate the unnecessary noise. We focus on what truly matters, streamlining the process to ensure that you have access to the essential information without distraction. By prioritizing the most relevant data, our platform empowers teams to build a more robust and efficient cybersecurity strategy.

Download Resources

Case Study - Team Backlog

— Trigger

  • Organization is in a firefighting mode.
  • Spending money is creating additional requirements, and open new attack vectors.

— Challenge

  • 23 facilities globally.
  • Inconsistency in results between regions.
  • Different solutions deployed on each site to mitigate the same threats.
  • New management has no visibility or historical data to rely on in decision making.

Novaigu Platform

  • Identify the organization risk profile.
  • Discover and assess assets to establish a cybersecurity baseline.
  • Implement a cyber security maturity roadmap.
  • Implement mitigations based on criticality to improve resilience.
  • Reassess on regular basis to measure maturity and budgeting requirement.

Case Study - Regulatory Compliance

— Trigger

  • Change in Regulatory and Compliance requirements.
  • Implement a cyber security program and assess their maturity on annual bases.
  • Three facilities in the US and Canada.

— Challenge

  • Large quantity of assets (170 network devices, 340 systems, 1000s of network connected field devices per site).
  • Reliance on the IT team to manage their assets.
  • Five specialized resources and six months to complete the task.

Novaigu Platform

  • Identify ICS/OT assets and define ownership, responsibility and accountability, and segregate OT and IT assets.
  • Reduce efforts, logistics and time required to one week per site.
  • Execute a vulnerability Assessment to evaluate weaknesses in security controls (per frameworks and standards) and provide a detailed and prioritized roadmap for the cybersecurity program.
  • No disruption to operators during the activities.
  • Reduce average cost from 340K to 120K a year.

Case Study - Expansions & Upgrades

— Trigger

  • Additional production units.
  • System upgrades and migrations.

— Challenge

  • Lack of staff and skills.
  • New systems interface with the existing environment.
  • Added complexity to inventory and managed assets.
  • Site has no visibility, and the new systems are adding risks.

Novaigu Platform

  • Immediately discover the new connected assets.
  • Scan security configurations on each asset and harden it.
  • Classify and organize assets based on use, functionality and criticality.
  • Execute a vulnerability Assessment to evaluate weaknesses in security controls, user access, patch, AV … etc.
  • Report on gaps and prioritize remediations based on compliances, security lifecycles and maturity levels.
  • The remediations (hardware, software, labor) can upon negotiations contracted to Novaigu professional services for implementation.